Description
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Order Export For WooCommerce CSV Injection (1.5.4)
Claroline Other Vulnerability (CVE-2005-1375)
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2023-28334)
WordPress Plugin Image Slider Arbitrary File Deletion (1.1.89)
Apache Tomcat URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-41080)